Open for applications

Dir, Priv & Data Protection Officer EMEA

logo of Johnson & Johnson

About the vacancy

IT
Business Solutions
Database
Cybersecurity
Data & Analytics
Enterprise Applications & Systems
IT Compliance & Validation
Regulatory Affairs
Regulatory compliance
Staff
Legal
Public Affairs
Director Bachelor’s Degree (HBO, WO) Permanent Full time Netherlands

About Your Next Job

Job Description:

DePuy Synthes is recruiting for a Director, Privacy Officer & DPO, EMEA


This role serves as the senior privacy leader for DePuy Synthes in the region, with accountability for privacy governance and formal Data Protection Officer (DPO) duties. The Director, Privacy Officer & DPO provides strategic leadership to ensure compliance with global and local data protection laws while enabling responsible innovation across a complex medical technology organization. This role has significant enterprise impact, partnering closely with Legal, IT, Security, Health Care Compliance, HR, Commercial, Clinical, Medical Safety and HEMA, and R&D teams to embed privacy‑by‑design across business operations and digital products.


About Your Tasks and Responsibilities

Key Responsibilities

  • Lead the implementation and ongoing oversight of the DePuy Synthes privacy program in the region, ensuring alignment with applicable local and regional data protection laws and regulations.
  • Advise business partners on privacy and data protection requirements in all stages of R&D, product development, commercialization, clinical trials, HEMA activities and lifecycle management.
  • Serve as the designated Data Protection Officer (DPO), acting as an independent advisor on data protection obligations and risk management.
  • Lead efforts to embed privacy capabilities in named privacy stewards from relevant functions, including handling escalations, driving consistency and delivering ongoing training and education to the stewards.
  • Identify any required regional-specific variants from global privacy policies, standards, and procedures to support compliant collection, use, transfer, and retention of personal data in the region.
  • Provide strategic guidance to business leaders on privacy risks associated with new products, digital health solutions, clinical activities, and commercial initiatives.
  • Oversee regional privacy impact assessments, data transfer assessments, and mitigation plans for high‑risk processing activities.
  • Partner with Information Security and Legal teams to support incident response, breach management, and regulatory communications in the region when required.
  • Lead privacy training and awareness programs to strengthen a culture of data protection and accountability across the organization.
  • Monitor regional regulatory developments and emerging privacy risks, translating requirements into practical business guidance.
  • Maintain external relationships with regional regulators and internal stakeholders to support audits, inquiries, inspections and data incident responses in conjunction with cross-functional partners.
  • Provide support for data contracting processes, including for escalations.


About Your Skills and Experience

Qualifications

Education

  • Bachelor’s degree required, preferably in Law, Information Systems, Business, or a related field required
  • Advanced degree (JD, LLM, MBA, or equivalent) preferred.

Experience and Skills

Required:

  • Minimum 10–12 years of progressive experience in privacy, data protection, cybersecurity or related legal roles, including leadership responsibility, including in a complex global corporation or private practice.
  • Demonstrated experience serving as, or supporting, a Data Protection Officer function within a regulated environment.
  • Experience in privacy data regulations in the healthcare industry.
  • Strong working knowledge of global privacy regulations (e.g., GDPR, APAC privacy frameworks) and their business application.
  • Proven ability to influence senior leaders and operate effectively in a complex, global organization.
  • Experience partnering with technology, security, and digital teams on privacy‑by‑design initiatives.

Preferred:

  • Specific data protection or privacy experience within medical devices, medtech, life sciences pharmaceutical industries or healthcare insurers or systems.
  • Experience supporting global or regional privacy programs across multiple jurisdictions.
  • Strong judgment, independence, and ability to manage sensitive matters with discretion and integrity.
  • Prior engagement with regulators and supervisory authorities.
  • Demonstrated people leadership or program leadership experience.

Other

  • Languages: Fluent in English required; German proficiency preferred.
  • Travel: Up to 20% international travel may be required.
  • Certifications (preferred): CIPP/E, CIPM, CIPT, or equivalent privacy certifications.


Where Molecules Meet Opportunities

Hybrid work


You are eligible to work in EU

We only accept applicants who are eligible to work in the EU


Contact person

logo of Johnson & Johnson

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com



Share this vacancy

Is it OK if we use cookies?

We use cookies to make our website and advertisements more personal and relevant. If you do not agree, we will only place functional and analytical cookies